StyleSmuggler Unpatched Magento Zero-Day Under Attack
Sansec issues advisory for StyleSmuggler, an unauthenticated zero-day RCE affecting Magento and Adobe Commerce without a patch.

Stock photo for illustration only, not from the actual event
- StyleSmuggler unpatched RCE vulnerability impacts current Magento versions
- Attackers deploy persistent backdoors disguised as Linux kernel threads
- Fully patched stores compromised despite commercial security shields
- Sansec recommends temporarily disabling GraphQL as an interim mitigation
Attackers are actively executing unauthenticated code on Magento and Adobe Commerce servers without an available patch. Dutch e-commerce security firm Sansec published an advisory on September 5, 2026, detailing a flaw dubbed StyleSmuggler, an unauthenticated remote code execution chain leading to a persistent backdoor on store servers. Exploitation commenced on September 4, and as of September 6, Adobe has yet to release an advisory, CVE identifier, patch, or official workaround.
Sansec reported that all current versions are affected, including 2.4.9, successfully reproducing the unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. The initial victim observed was running version 2.4.6-p15 with Adobe's July and August 2026 security updates applied, representing the highest patch level available for the 2.4.6 line. Being fully up to date did not prevent the breach.

Stock photo for illustration only, not from the actual event
Zero-day vulnerabilities targeting core enterprise platforms regardless of patch status highlight the critical limits of traditional reactive security. Relying solely on routine software updates or standard web application firewalls is often insufficient against sophisticated supply chain and framework exploits.
Independent confirmation emerged from Disrex Group, a Magento hosting and development firm that managed two compromised stores and one targeted site. Store A ran version 2.4.8 with an active Sansec Shield module and was breached on September 4, 2026, at 23:10 UTC, hours before specific blocking rules were released. Store B ran version 2.4.7-p2 and was hit on September 5, 2026, at 00:55 UTC.
"Patch status was irrelevant here, which is the part merchants most need to hear"
Disrex
The payload bypasses traditional PHP webshell locations in the web root. Sansec indicators reveal a background process disguised as [kworker/u:8:0], mimicking a legitimate Linux kernel thread, running from a binary within the site user's home directory. Disrex characterized the binary as a stripped, statically linked Rust program of approximately 1.9 MB built for x86-64 and arm64 architectures.
Sansec's primary interim mitigation for merchants lacking its Shield product is to temporarily disable GraphQL until Adobe delivers an official fix. Store administrators should monitor host systems closely and await Adobe's scheduled September 8 security release.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment